bountysource / bountysource/core
Fine-grained github permissions
Open
GitHub plugin
- Dominant language
- Ruby
- Stars
- 643
- Forks
- 199
- PR merge metrics
- No merged PRs in 30d
Description
I would like to use the github plugin for one of my repositories, but while installation bountysource requests permissions to all organisations which I am part of. This feels very insecure and in the case bountysource get hacked this could result in big trouble. I would feel a lot better if bs could request permissions only for repositories or organisations which are needed to install the plugin.
Contributor guide
Assessment
This issue has not been assessed yet.